fuzzing-untrusted-inputs
Use when fuzzing untrusted inputs is required during quality work, especially when the result must be traceable, independently reviewable, and safe to hand to another agent.
npx skills add casioreview20-glitch/forge-os --skill fuzzing-untrusted-inputs --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
# Fuzzing Untrusted Inputs ## Overview This skill owns one bounded responsibility: **fuzzing untrusted inputs**. Its focus is exercise parsers, protocol boundaries, file formats, and user-controlled fields with structured malformed input. It converts declared inputs into typed artifacts and reproducible evidence without silently changing product scope. ## Trigger Activate only when the project is in one of these stages: `verification`, all contract preconditions pass, and the router identifies a missing output this skill can produce. Do not activate merely because the skill name resembles the user request. ## Required Inputs - `test-plan` - `verified-build` - Optional: `domain-evidence` - Current gate result, open findings, artifact hashes, and invalidation state - Required tools: `test-runner` - Optional tools: none - Confirmed human decisions relevant to this scope ## Method-Specific Protocol 1. Inventory every decoder and externally controlled byte or value boundary. 2. Build seed corpora from valid examples, historical failures, boundary values, and protocol dictionaries. 3. Define crash, timeout, memory, invariant, authorization, and differential oracles. 4. Run mutation or gr
- Overview
- Trigger
- Required Inputs
- Method-Specific Protocol
- Procedure
- Verification Questions
- Evidence Packet
- Output Contract
- Quality Gate
- Forbidden Shortcuts
- Failure Modes
- Escalation and Invalidation
- Handoff
- Token and Context Policy
What does the fuzzing-untrusted-inputs skill do?
Use when fuzzing untrusted inputs is required during quality work, especially when the result must be traceable, independently reviewable, and safe to hand to another agent.
How do I install it?
Run `npx skills add casioreview20-glitch/forge-os --skill fuzzing-untrusted-inputs --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From casioreview20-glitch/forge-os, a repository with 11 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.